Security & governance

Enterprise-grade
trust, by design.

Grounded, governed AI on your own data and infrastructure – encrypted, access-controlled, and aligned with recognised security and AI-governance standards from day one, never bolted on after go-live.

ISO 9001 · ISO 27001 · CMMI Level 3 · PDPA-ready · On-premise / private cloud · Data residency in-region · Backed by DEHA Group (Singapore · Vietnam · Japan)
/ Security posture

Built secure, not bolted on.

Security and compliance are part of the architecture – decided in the design phase, enforced on every layer, not a checklist added before launch.

Encryption

All data encrypted in transit (TLS 1.2+) and at rest (AES-256), across every environment.

Role-based access control

Least-privilege RBAC enforced by default on every product; SSO-ready (Google, Microsoft).

Permission-aware retrieval

Answers respect your source permissions — the assistant only surfaces what a user is already allowed to see.

Audit logs

Full audit logging of every access and data change, retained per your corporate policy.

/ Certifications & standards

Certifications that back the delivery.

These certifications are held by DEHA’s software-delivery organisation and govern how we build and run your deployment. Status is shown honestly — updated as each milestone completes.

ISO 27001

Information security management - audited and certified (delivery org).

Certified

CMMI Level 3

Appraised process maturity across our delivery organisation.

Appraised

PDPA-ready

Data-handling, consent and breach-notification principles built into every deployment (Singapore PDPA).

Aligned

MAS TRM

Architecture aligned to the Technology Risk Management guidelines for MAS-regulated financial-services clients.

Aligned

APPI (Japan)

Data-handling aligned to Japan's Act on the Protection of Personal Information for enterprise deployments.

Aligned

Backed by DEHA Group — 600+ projects · 200+ clients · 200+ engineers · 4 offices across APAC (SG · VN · JP) ·
/ Data governance

Your data stays yours.

We process personal data under Singapore’s PDPA (2012) – and GDPR where it applies to EEA users. Controller: DEHA GLOBAL PTE. LTD. For data inside your Workspace, your organisation is the controller and we act as processor.

You own your content

You keep full ownership of your documents and data. We hold a limited licence only to store, index and process them to run the service for you.

Never used to train shared models

Your content is never sold and never used to train models shared with other clients, unless you explicitly opt in.

Data residency in-region

Data stays in the cloud region you designate; no cross-border transfer without your written agreement (SCC / equivalent safeguards when it applies).

Trial data auto-deleted

Free-trial data is deleted after the trial. On deletion of content or account, related data is deleted or anonymised within a reasonable period, unless law requires longer retention.

Your rights (PDPA / GDPR)

Access, correct, delete, restrict, object, port, and withdraw consent — via info@deha-global.com; we respond within statutory timelines.

Workspace isolation

Separate, isolated environments per client — no shared multi-tenant data stores.

/ AI governance

Governed the way Singapore expects.

Aligned – not certified – with Singapore’s Model AI Governance Framework for Generative AI. We operate along its six dimensions:

01

Accountability

Clear ownership of the deployment: named roles, DPAs, and mutual NDAs before any data is shared.

02

Data

Governed data handling — provenance, consent, residency and minimisation across the pipeline (see Data governance).

03

Trusted development & deployment

Baseline safety and hygiene in how models are integrated, tested and shipped — grounded, source-cited answers over open-ended generation.

04

Incident reporting

Monitoring plus a documented incident-response and breach-notification process, with timelines aligned to your regulatory obligations.

05

Testing & assurance

Evaluation before go-live; we support client-initiated penetration tests on your deployment environment.

06

Security

Information-security controls adapted for GenAI threat vectors – encryption, RBAC, permission-aware retrieval, audit logs.

/ Deployment

Deploy it where your data has to live.

Run it where your policy requires – you keep the data and the keys; we run the platform to your configuration.

Option
Where it runs
Best for
Data residency
Your cloud
Your AWS region (Azure on request)
Fast rollout on trusted infrastructure
Your designated region
On-premise
Your own servers (binary + license key)
Strict data sovereignty / regulated work
Fully in your datacentre
Managed by DEHA
DEHA-operated, isolated per client
Teams that want us to run it
Region you designate
Air-gapped
Fully offline (local models)
No-internet / classified environments
Never leaves your network
/ Trust in the product

Answers you can defend.

Trust isn’t only infrastructure – it’s how the assistant answers.

Source-cited

Every answer cites the documents it came from, so your team can verify before they act.

No answer without a source

If the knowledge base doesn’t support it, the assistant says so instead of guessing.

Permission-aware

Retrieval respects your access rules — users only see what they’re already entitled to.

Framework by IMDA · AI Verify Foundation.
/ Sub-processors

Who we rely on, and what they touch.

To run the service we use a small set of vetted sub-processors, each bound by data-protection terms and used only on our instructions. The full, named list is available on request and in our DPA.

Category
Purpose
Where data is processed
AI model & inference providers
Generate answers, embeddings and document processing
Region-scoped to your deployment
Cloud hosting & storage
Host the service and store your content
Your designated region
Payment processing
Billing for paid plans
Provider region
Email & communications
Transactional email and trial follow-ups
Provider region
/ Incident response

If something goes wrong, you'll know.

Continuous monitoring, a documented response process, and breach-notification timelines aligned to your regulatory obligations – agreed per engagement.

Monitor

Access and data-change logging with anomaly monitoring across environments.

Respond

A documented incident-response runbook, customised per engagement.

Notify

Breach notification within timelines aligned to your obligations (PDPA / GDPR / sector rules).

Verify

We support client-initiated penetration tests, coordinated to avoid service disruption.

/ Resources

Send this to your security team.

The evidence your security and legal reviewers will ask for – available on request under NDA.

Security whitepaper

Architecture, data flows and controls in one document.

Data Processing Agreement (DPA)

Our standard DPA and sub-processor terms, including the named list.

Certificates & pen-test summary

ISO 27001, CMMI Level 3 certificates and the latest test summary.

/ FAQ

Questions your security
& legal team will ask.

Where is our data stored?

In the cloud region you designate (AWS today; Azure on request), on-premise, or air-gapped. We don’t move data across regions without your written agreement.

Only roles you authorise, via role-based access control. Every access and change is logged and auditable.

No. Your documents and data are used only within your deployment — never to train models shared with other clients, unless you explicitly opt in.

A documented incident-response process applies per engagement, including breach-notification timelines aligned to your regulatory obligations.

Yes. We support client-initiated pen tests on your deployment environment, coordinated with our team to avoid disruption.

Yes — mutual NDAs and Data Processing Agreements are standard before any data is shared or work begins.

ISO 27001, CMMI Level 3 (delivery organisation). PDPA, MAS TRM and Japan APPI are addressed by design. We’re aligned with Singapore’s Model AI Governance Framework for Generative AI.

Ready for a security deep-dive?

Start a free 3-day trial on your own data – on-premise / private cloud, auto-deleted after the trial – or send this page to your security team.